Files
flock/deploy/rbac/serviceaccount.yaml
T
Donavan Fritz 759ed21b37
Build flock Image / build (push) Has been cancelled
M1.5: NodeConfig dynamic informer + RBAC
Agent now watches nodeconfigs.flock.fritzlab.net via a client-go dynamic
informer, filters events to its own node name, and caches the typed
NodeConfig in memory (NodeConfigCache, atomic pointer). M2's IPAM will
read from that cache.

- pkg/agent/nodeconfig.go: informer + JSON-round-trip decode (avoids
  hand-written DeepCopy + scheme registration for this small a use).
- pkg/agent/server.go: starts the informer goroutine; Run terminates if
  the informer returns.
- pkg/api/v1alpha1: switch placeholder TypeMeta/ObjectMeta to metav1.
- deploy/rbac: get/list/watch on nodeconfigs.
- cmd/flock-agent: --kubeconfig flag for out-of-cluster runs (tests).

Satisfies M1 verified-by: "kubectl apply NodeConfig; agent logs read it".

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
2026-04-24 22:00:48 -05:00

29 lines
644 B
YAML

apiVersion: v1
kind: ServiceAccount
metadata:
name: flock-agent
namespace: kube-system
---
# M1.5 RBAC: just enough to read NodeConfig. M2 adds pods + networkpolicies.
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: flock-agent
rules:
- apiGroups: ["flock.fritzlab.net"]
resources: ["nodeconfigs"]
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: flock-agent
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: flock-agent
subjects:
- kind: ServiceAccount
name: flock-agent
namespace: kube-system